HelloFresh
Senior Security Engineer (SOC) (m,f,x)
Berlin, Berlin, Germany
Get past the screening software and onto a recruiter's desk
hirly rewrites your resume for this job — matching the keywords and skills in the posting, moving your most relevant experience to the top, and writing a cover letter to fit. About 30 seconds.
- Keywords matched to this posting
- Fit score before you apply
- Cover letter included
Matched against 2.4M live jobs from 200,000+ employers in 200+ countries.
Tailor my resume for this job →Apply from your AI assistant
Connect hirly to Claude and ask it to apply to this job. hirly tailors your resume, fills the employer’s form and asks before sending. ChatGPT: manual setup today.
Some employer sites stop an application at a CAPTCHA or sign-in and hand it back with a link. Applying needs a paid plan. Works with any assistant that supports MCP.
hirly's read of this role
- Role family
- Engineering
- Seniority
- Senior
- Country
- DE
- Work mode
- On-site / unstated
- First seen by hirly
- 11 Sept 2026
Derived automatically from the posting. Upload your resume above to see how the role scores against it.
the posting
About the role: What's in the Box
We’re looking for a new teammate to join us on the journey of keeping HelloFresh a trusted name - someone with a passion for security and appetite for new challenges. Security Engineers work in a variety of ways to constantly iterate and improve HelloFresh’s security posture.
As an Experienced SOC Analyst at HelloFresh, you’ll bring advanced expertise to our SOC team in Manila. Working in a flat team structure, you’ll act as a Senior Engineer handling escalations from junior analysts, driving complex investigations, and ensuring accurate incident reporting.
You’ll be the point of contact for Berlin SOC leadership during major incidents, mentor junior colleagues, and help refine SOC processes. This is a hands-on technical role with strong responsibility, requiring both depth in incident response and leadership qualities to keep the operations effective
Above all, we are looking for people who will make HelloFresh better. We believe there are many different ways of developing skills and we love diverse experiences! So even if you don’t “tick all the boxes” but think you’d thrive in this role, we would really like to learn more about you.
What You’ll Do: The Recipe
Responsible for maturing logging and monitoring of Cloud, IT and Application workloads through automation and IaC
Filter, ingest and optimize security-specific events from large log streams such as App logs, Kubernetes logs, CloudTrail, CloudFlare and ELB logs etc.
Conduct threat hunts against file-less malware and APTs by leveraging EDR, OS and network telemetry acquired through specialized open-source tool set like Sysmon, Osquery, RITA and Zeek
AI-Enhanced Coding: Ability to use AI coding assistants to write scripts for security automation and data parsing and building detection logic.
Investigation Acceleration: Proficiency in using LLMs (e.g., Claude, ChatGPT, Gemini) to quickly summarize high-volume JSON logs, investigate and explain complex code snippets etc.
Develop advanced correlation and cross-correlation rules beyond what is available out of the box to detect sophisticated attacks and fraud cases
Generate security metrics and reporting on incidents and effectiveness of the SOC operation
Lead efficient Incident Detection and Response in AWS cloud and enterprise IT environments
Shift Communication: Serve as the shift’s main communicator, updating Berlin SOC leadership and local IT/business stakeholders during active incidents.
Playbook & Process Improvement: Suggest detection rule tuning, SOP refinements, and contribute to the team knowledge base to reduce false positives and improve workflows.
Mentor level (L1) SOC team, conduct purple teaming workshops and participate in CTFs
What You’ll Bring: The Ingredients
Proven security monitoring and incident response experience in public cloud environments
Experience with cloud SIEM & SOAR platforms, DDoS mitigation and preventing tools and Layer-7 Web-based perimeter security controls
Excellent programming (automation) skill with Python / Go
Experience with cloud SIEM & SOAR platforms, DDoS mitigation and preventing tools and Layer-7 Web-based perimeter security controls
AI-Enhanced Coding: Ability to use AI coding assistants to write and debug Python scripts for security automation and data parsing.
Detection Logic: Proficiency in writing detection rules (Sigma, KQL) with the assistance of AI tools to optimize query performance and coverage.
Understanding of network intrusion methods, network containment, segregation techniques and technologies such as Sandboxes and Intrusion Detection/Prevention Systems (ID/PS)
Ability to analyze disparate log sources on demand and cut noise from the signal
Good communication and reporting skills
Command over log analysis stacks like ElasticSearch, Splunk/SumoLogic, Graylog
Open to working on-call in rotational shifts
Meeting response time and incident closure metrics, with thorough documentation and timely stakeholder updates.
What we Offer: The Toppings
Elevate your lifestyle! Join one of Europe's fastest-growing tech powerhouses in a dynamic phase of expansion.
Immerse yourself in a diverse global community of 90+ nationalities.
Enjoy a competitive compensation package that goes beyond the norm, with perks like a HelloFresh- subsidized Pension Scheme and a Hybrid working model.
Elevate your lifestyle with exclusive discounts on your weekly HelloFresh box and office meals.
Invest in your growth with a German language learning budget, and access to the HelloFresh Academy.
Plus, we've got your well-being covered with mental health support, transportation perks, and working-parent-friendly benefits. From our 24/7 gym access,wellbeing platforms like Headspace and Spill, to sabbatical leave options, HelloFresh is not just a workplace; it's a lifestyle of perks and possibilities!
Similar jobs
- Senior IT-Security Engineer (m/w/d)Orizon GmbH, Unit Aviation · Flintbek, Schleswig-Holstein, GermanyFirst seen today
- Security EngineerAugustus · BerlinFirst seen yesterday
- Application Security Engineer (f/m/d)Awin · Berlin, Berlin, Germany; Madrid, Madrid, Spain; Milano, Milan, Italy; Warsaw, Masovian Voivodeship, PolandFirst seen 2d agoremote
- Senior Security EngineerFreiheit 2 · HamburgFirst seen 3d ago
- Senior Security Engineer - SecOpsMozilla · RemoteFirst seen 3d agoremote
Browse similar roles
Want this one?
Upload your resume and hirly rewrites it for this job and writes the cover letter — in about thirty seconds, before you sign up.
Tailor my resume for this job